Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b2bc88ba by Moritz Muehlenhoff at 2026-08-14T12:43:00+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -441,6 +441,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable
of forging up to two
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80744
@@ -452,6 +453,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving
arbitrary module cont
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80745
@@ -463,6 +465,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the
depth counter causing
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80481
@@ -474,6 +477,7 @@ CVE-2026-56853 (When a server is configured to support
unencrypted HTTP/2, it re
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80205
@@ -485,6 +489,7 @@ CVE-2026-56860 (Previously, resolving relative paths
containing parent directory
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80494
@@ -496,6 +501,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are
always considered as
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80528
@@ -507,6 +513,7 @@ CVE-2026-56858 (Previously, pathological inputs could close
an unescaped '/' ear
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80435
@@ -518,6 +525,7 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to
prevent stack exhausti
- golang-1.26 <unfixed> (bug #1144341)
- golang-1.25 <unfixed> (bug #1144342)
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-1.15 <removed>
NOTE: https://github.com/golang/go/issues/80405
@@ -1468,15 +1476,18 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a
hard-coded cluster-authentica
NOT-FOR-US: WolfStack
CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior
to 0.144 ...)
- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
NOTE: Fixed by:
https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da
(v0.144.0)
CVE-2026-73500 (etcd is a distributed key-value store for the data of a
distributed sy ...)
- etcd <unfixed> (bug #1144346)
+ [trixie] - etcd <no-dsa> (Minor issue)
NOTE:
https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
NOTE: https://github.com/etcd-io/etcd/pull/22130
NOTE: Fixed by:
https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057
(v3.5.33)
CVE-2026-73499 (etcd is a distributed key-value store for the data of a
distributed sy ...)
- etcd <unfixed> (bug #1144346)
+ [trixie] - etcd <no-dsa> (Minor issue)
NOTE:
https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
NOTE: Fixed by:
https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7
(v3.5.33)
CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for
Atlassian p ...)
@@ -2497,12 +2508,14 @@ CVE-2026-73243 (kkFileView is a universal file online
preview project based on S
NOT-FOR-US: kkFileView
CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
- freerdp3 3.30.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
NOTE: Fixed by:
https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc
(3.30.0)
CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop
Protocol. Prior ...)
- freerdp3 3.30.0+dfsg-1
+ [trixie] - freerdp3 <no-dsa> (Minor issue)
- freerdp2 <removed>
NOTE:
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x
NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
@@ -2657,6 +2670,7 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an
authorization bypass (insecure
- snipe-it <itp> (bug #1005172)
CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command
is gated ...)
- freeipa <unfixed>
+ [trixie] - freeipa <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514019
CVE-2026-19217 (The Royal Addons for Elementor WordPress plugin before
1.7.1065 does ...)
NOT-FOR-US: WordPress plugin
@@ -3154,10 +3168,12 @@ CVE-2026-72712 (Nmap versions up to and including 7.99
contains a denial of serv
NOTE: Crash in CLI tool, no security impact
CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a
root us ...)
- mrtg <unfixed>
+ [trixie] - mrtg <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
NOTE: Fixed by:
https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current
VT and th ...)
- kbd <unfixed>
+ [trixie] - kbd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462115
NOTE: Fixed by:
https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698
(v2.10.0)
CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17,
25.05.1 ...)
@@ -5004,6 +5020,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate
client certificates in
NOT-FOR-US: SAP
CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a
process ...)
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
NOTE: Fixed by:
https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b
(v12.6.0-rc2)
CVE-2026-5304 (An ACAP configuration file lacks input validation, which could
potenti ...)
@@ -5445,6 +5462,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger-
provided by Nishishi Factory
NOT-FOR-US: Nishishi Factory
CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or
convert op ...)
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
NOTE: Fixed by:
https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825
(v12.6.0-rc2)
CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL
injection ...)
@@ -10725,6 +10743,7 @@ CVE-2026-18322 (The Smart Popup by Supsystic plugin for
WordPress is vulnerable
NOT-FOR-US: WordPress plugin
CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with
network access ...)
- isc-dhcp <removed>
+ [trixie] - isc-dhcp <ignored> (ISC DHCP not covered by security support
in Trixie)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2508081
CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate
Listings WordPr ...)
NOT-FOR-US: WordPress plugin
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits